Introduction
Evidence theory
Reliability of intrusion detection system
Alert fusion method
-
The Dempster–Shafer rule does not incorporate the reliability of source whose evidences are to be fused. Thus, there is no real-time criteria which assign a numerical value of reliability to the evidence given by the source.
-
The Dempster–Shafer rule considered all the sources of evidence to be equally reliable. However, in fusion framework, there might be some unreliable sources which mislead the fusion rule to give wrong decision.
-
Another drawback in Dempster–Shafer rule as suggested by Goodman [3] is that in an environment consisting of many hypotheses and many sources, it is difficult to decide whether to accept or reject the result of such fusion rule. If sources of evidences are highly conflicting, the DS rule completely fails. If analyst blindly believes on the result, then the decision can be misleading or complementary.
Attack type | Sub attack types |
---|---|
DOS | Smurf, teardrop, pod, back, land, apache2, udpstrom, mailbomb, processtable, Neptune |
Probe | Ipsweep, portsweep, nmap, satan, saint, mscan |
U2R | Bufferoverflow, rootkit, perl, loadmodule |
R2L | Imap, ftpwrite, guesspasswd, multihop, phf, spy, warezclient, warezmaster |
Snort | Suricata | PHAD | NETAD | Fusion with DS rule | Fusion with proposed rule | |
---|---|---|---|---|---|---|
TPR | 0.5129 | 0.4974 | 0.5221 | 0.4938 | 0.5185 | 0.5314 |
FPR | 0.5093 | 0.5099 | 0.5172 | 0.4987 | 0.5218 | 0.0073 |
PPV | 0.5642 | 0.5564 | 0.5648 | 0.5601 | 0.5609 | 0.9895 |
NPV | 0.4393 | 0.4313 | 0.4400 | 0.4351 | 0.4358 | 0.6223 |
ACCURACY | 0.5032 | 0.4942 | 0.5049 | 0.4971 | 0.5009 | 0.7332 |
Experimental setup
KDD99 dataset
Snort | Suricata | PHAD | NETAD | Fusion with DS rule | Fusion with proposed rule | |
---|---|---|---|---|---|---|
TPR | 0.4712 | 0.5221 | 0.5051 | 0.4681 | 0.4985 | 0.5216 |
FPR | 0.4788 | 0.4954 | 0.4914 | 0.4960 | 0.4940 | 0.0146 |
PPV | 0.5545 | 0.5754 | 0.5693 | 0.5482 | 0.5647 | 0.9788 |
NPV | 0.4339 | 0.4509 | 0.4443 | 0.4243 | 0.4397 | 0.6160 |
ACCURACY | 0.4931 | 0.5145 | 0.5067 | 0.4838 | 0.5017 | 0.7248 |